using-git-worktrees
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands for environment management, including directory navigation, Git worktree operations, and executing project-specific test runners.
- [EXTERNAL_DOWNLOADS]: The skill automates the download and installation of project dependencies using established package managers such as npm, pip, poetry, cargo, and go from their official registries.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from local repository files to guide its execution logic, creating a potential attack surface if those files are malicious.
- Ingestion points:
CLAUDE.md,package.json,Cargo.toml,requirements.txt,pyproject.toml,go.mod. - Boundary markers: None; the skill implicitly trusts the repository content for its configuration.
- Capability inventory: Git operations, file system modification (worktree creation), network access (via package managers), and arbitrary code execution (via
npm test,pytest, etc.). - Sanitization: No validation or sanitization is performed on the values extracted from the configuration files.
Audit Metadata